Ongoing PLC Exploitation Against Critical U.S. Infrastructure
Essential information
- Published
- 24/07/2026 14:34
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- critical infrastructure energy sector hmi manipulation industrial control systems iocontrol irgc-cec malpdb ot security plc exploitation water facilities
- Related entities
- 23 indicators, 23 observables, 1 intrusion sets (apt), 20 techniques (mitre), 2 malware
Description
Multiple federal agencies have updated a joint advisory warning of active exploitation targeting programmable logic controllers (PLCs) in U.S. critical infrastructure. Attackers scan for internet-exposed industrial control systems and connect using legitimate engineering software with valid credentials, appearing as authorized technicians. Once inside, they alter controller logic and manipulate operator displays to hide anomalies. The campaign has expanded beyond Rockwell Automation to include Schneider Electric and Siemens equipment. Unlike a similar 2023 campaign that caused minimal disruption, this ongoing activity has resulted in confirmed operational disruption and financial losses. Targeted sectors include government facilities, water systems, and energy infrastructure. The exploitation leverages architectural weaknesses rather than software vulnerabilities, with attackers accessing systems through ports 22, 102, 502, 2222, and 44818.